-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 22 Jun 2023 14:47:22 +0200 Source: asterisk Binary: asterisk asterisk-dahdi asterisk-dahdi-dbgsym asterisk-dbgsym asterisk-mobile asterisk-mobile-dbgsym asterisk-modules asterisk-modules-dbgsym asterisk-mp3 asterisk-mp3-dbgsym asterisk-mysql asterisk-mysql-dbgsym asterisk-ooh323 asterisk-ooh323-dbgsym asterisk-tests asterisk-tests-dbgsym asterisk-voicemail asterisk-voicemail-dbgsym asterisk-voicemail-imapstorage asterisk-voicemail-imapstorage-dbgsym asterisk-voicemail-odbcstorage asterisk-voicemail-odbcstorage-dbgsym asterisk-vpb asterisk-vpb-dbgsym Architecture: armhf Version: 1:16.28.0~dfsg-0+deb11u3 Distribution: bullseye-security Urgency: high Maintainer: arm Build Daemon (arm-ubc-04) Changed-By: Markus Koschany Description: asterisk - Open Source Private Branch Exchange (PBX) asterisk-dahdi - DAHDI devices support for the Asterisk PBX asterisk-mobile - Bluetooth phone support for the Asterisk PBX asterisk-modules - loadable modules for the Asterisk PBX asterisk-mp3 - MP3 playback support for the Asterisk PBX asterisk-mysql - MySQL database protocol support for the Asterisk PBX asterisk-ooh323 - H.323 protocol support for the Asterisk PBX - ooH323c asterisk-tests - internal test modules of the Asterisk PBX asterisk-voicemail - simple voicemail support for the Asterisk PBX asterisk-voicemail-imapstorage - IMAP voicemail storage support for the Asterisk PBX asterisk-voicemail-odbcstorage - ODBC voicemail storage support for the Asterisk PBX asterisk-vpb - VoiceTronix devices support for the Asterisk PBX Changes: asterisk (1:16.28.0~dfsg-0+deb11u3) bullseye-security; urgency=high . * Non-maintainer upload. * Fix CVE-2023-27585: A flaw was found in Asterisk, an Open Source Private Branch Exchange. A buffer overflow vulnerability affects users that use PJSIP DNS resolver. This vulnerability is related to CVE-2022-24793. The difference is that this issue is in parsing the query record `parse_query()`, while the issue in CVE-2022-24793 is in `parse_rr()`. A workaround is to disable DNS resolution in PJSIP config (by setting `nameserver_count` to zero) or use an external resolver implementation instead. Checksums-Sha1: 8d4166c7e4d4fd01f7baac57d7e97f35e8c02c9d 646820 asterisk-dahdi-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 431ea2d9912831abd1221f8a2587465655c9ed37 1573768 asterisk-dahdi_16.28.0~dfsg-0+deb11u3_armhf.deb 6016e85fb41c995b3038ab1b4ce1d7b885560edf 6400836 asterisk-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb eb6c4713cca313420021d3c483b0d18e2bc2f45d 86444 asterisk-mobile-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb ef548152314ad669425aef8ae0998dc52c2d3d95 1374456 asterisk-mobile_16.28.0~dfsg-0+deb11u3_armhf.deb 43eaf44316e1acf80069dac0e723ff1020d8ab96 10167264 asterisk-modules-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 976816519271141ab78bd24886bca3fc68a81d53 3853356 asterisk-modules_16.28.0~dfsg-0+deb11u3_armhf.deb 8d1969bb91a15579ee7013b754f487f3d764cd86 50576 asterisk-mp3-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb aa8d3d0b1b268d4d644549a1f98c1d7e7b826b08 1357944 asterisk-mp3_16.28.0~dfsg-0+deb11u3_armhf.deb fd287c39c85969fbf8f15f85fad775c1f0569a32 134656 asterisk-mysql-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 6673e6f6b21b68c752d372797fdb3e501e44c87c 1375288 asterisk-mysql_16.28.0~dfsg-0+deb11u3_armhf.deb 500e165d08f55feef6c7e8305c5a448b704e475d 1469100 asterisk-ooh323-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb c0b68d5a327cfd81c3bfdef114ef06f84d2f5c1b 1631772 asterisk-ooh323_16.28.0~dfsg-0+deb11u3_armhf.deb 9307470eb47f3b2276a92fd2cfc8dcd6567c04c7 1433292 asterisk-tests-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 0142d0368981bfd7106ec797ceaf448c9163b6c3 1808744 asterisk-tests_16.28.0~dfsg-0+deb11u3_armhf.deb 9ca16f2cdc6ddc951a53ba88fbad725bb94fc90a 272104 asterisk-voicemail-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 4ff6aa34d726b157c198d798861faa1de18ed8be 320660 asterisk-voicemail-imapstorage-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 754d2a157d5a4d09ba716f22a6d68951580724f6 1454448 asterisk-voicemail-imapstorage_16.28.0~dfsg-0+deb11u3_armhf.deb 1eddb37e023d3cd3fff8b592831ca6c8a8f881d4 285544 asterisk-voicemail-odbcstorage-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 2165d6a23c30a7e43d8bcbed71b1b9fead96e360 1441664 asterisk-voicemail-odbcstorage_16.28.0~dfsg-0+deb11u3_armhf.deb 68ce315fa9daadc9b48c384039cfc117593d47ec 1435748 asterisk-voicemail_16.28.0~dfsg-0+deb11u3_armhf.deb 67daf283f18f97f6d58b0552bd7f440b38ef33a1 69972 asterisk-vpb-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 0010ce404ca8cf12d192f8280f5b0cb424b076cf 1362604 asterisk-vpb_16.28.0~dfsg-0+deb11u3_armhf.deb e406b14973e7d710909b1831c1b7d01aa34c88b4 27500 asterisk_16.28.0~dfsg-0+deb11u3_armhf-buildd.buildinfo ac042144fffa12667472f058bf78a9062ca3c134 2221012 asterisk_16.28.0~dfsg-0+deb11u3_armhf.deb Checksums-Sha256: 56e139ab774b36cfcc4b8b2f24c6368b759ceb965a452e97e5e6403bbb75019b 646820 asterisk-dahdi-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 54a26ecf4d69cb4f3c781c97667e7f1babd959a61ce92aedadd1eef667d19fdf 1573768 asterisk-dahdi_16.28.0~dfsg-0+deb11u3_armhf.deb 843af9513d46ef3f019843a872a879041ee237c6e1b52b9dc4c6971ebb419e1a 6400836 asterisk-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 88145fdc844650d22244db0d20d2bb6cdedba3216595a96467825bbd7d455ed3 86444 asterisk-mobile-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 3b1f31b0e30c42bbc307d95f19bcf09a373b253f30c1689bdf00a72444a95aa2 1374456 asterisk-mobile_16.28.0~dfsg-0+deb11u3_armhf.deb 5d6d74d5723698872ace49e11671ce30c03652d7af9600ed1e52fbe048d81969 10167264 asterisk-modules-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb a1961afcbad433b417bedd167419b046bfd9292246f67fee3a862e2e15b581b8 3853356 asterisk-modules_16.28.0~dfsg-0+deb11u3_armhf.deb 123532e35c77ecaa286c95d1048fc90edd68cd5626ae7cef03fa4e8d19617539 50576 asterisk-mp3-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 5c9bbd2a2ee1dece173ae51adf7d7441d75c59969e1e3c53df1313102e1f819d 1357944 asterisk-mp3_16.28.0~dfsg-0+deb11u3_armhf.deb 71d677a9ddd75e3682d4c29c2fe2445ad7843bccd129f5913e95af5815fa99f4 134656 asterisk-mysql-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 3ddbe68ff7b838c4922434b9da0f31013501049626f03488aae8658e1cabf01b 1375288 asterisk-mysql_16.28.0~dfsg-0+deb11u3_armhf.deb e1a891cab08556e628f06c4888f8161101da643c623277f6c9b43a1573f6c80a 1469100 asterisk-ooh323-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 1aa6e226f711586a9e7989266a20adfe2aa8ecd80969ed68914ba377b07ddf2b 1631772 asterisk-ooh323_16.28.0~dfsg-0+deb11u3_armhf.deb ccf8436adf3dba88a4ec817a4ebfececc6da34b33d09a3df358ecf4d5b9c4b87 1433292 asterisk-tests-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb b5f04b177c8c17237b15fb4f21b48fbdcb977e92c345a4ce4b8534ae62991eed 1808744 asterisk-tests_16.28.0~dfsg-0+deb11u3_armhf.deb 9a5a04e00f8b42d9ff4e9798838ba6c25ce5889bb34fe880f316da36034b9197 272104 asterisk-voicemail-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 00759fb648fdd3f8fd82e52d98f961df5ffddd9b9acfc753f64a32ba84ac1c72 320660 asterisk-voicemail-imapstorage-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb e95836b376497d3c95820d469510d712e9cb345c98cee3f006b8665d77c1ffd9 1454448 asterisk-voicemail-imapstorage_16.28.0~dfsg-0+deb11u3_armhf.deb 5227dde71596f3409566f27c9d46d0b4605cdc5cc7424158d8e3c13849299c80 285544 asterisk-voicemail-odbcstorage-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb e8f45ecbf8a06b731b1c272bd28686ec22a8652643363a33d844426fabe01d70 1441664 asterisk-voicemail-odbcstorage_16.28.0~dfsg-0+deb11u3_armhf.deb fb729f40f0b7a1c7a24b02bd83dfbba7160063eb7d8dbdd3978c5b59b10efa7b 1435748 asterisk-voicemail_16.28.0~dfsg-0+deb11u3_armhf.deb 6b1930ac17cb52d070fb8fed77c7e1de97194395f17eb07e27d52c1ebbb2d6dc 69972 asterisk-vpb-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 9e3a81a26bd9850d33f11eae8d32eef6b785f8432ed52d7b494e3d98ee69c235 1362604 asterisk-vpb_16.28.0~dfsg-0+deb11u3_armhf.deb b67a3c7355d6b6c229f20d97e2acdb9a09c51470a64f89123f0377eac9532389 27500 asterisk_16.28.0~dfsg-0+deb11u3_armhf-buildd.buildinfo 278d2bb34bbb00574edf4a99d62206513436ed31c8f6d956eb048179e13e8240 2221012 asterisk_16.28.0~dfsg-0+deb11u3_armhf.deb Files: c8fea435932d4695d9ec0dd2e76f4ef0 646820 debug optional asterisk-dahdi-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 189a70a1196814411125b351833892ed 1573768 comm optional asterisk-dahdi_16.28.0~dfsg-0+deb11u3_armhf.deb 5e2b20dde7d32970c7f51a74ae5a1544 6400836 debug optional asterisk-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 4b4e401674a97690d6cf355daccf0797 86444 debug optional asterisk-mobile-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 81e3fbd42c8ee8d11f9dd7e8fa145f97 1374456 comm optional asterisk-mobile_16.28.0~dfsg-0+deb11u3_armhf.deb 66a84cd8ba16a6ee1c081729843873cf 10167264 debug optional asterisk-modules-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb db864eaa03b67d201ab2062fada270ae 3853356 libs optional asterisk-modules_16.28.0~dfsg-0+deb11u3_armhf.deb be00cf488afe69232a3fe1c2469318a6 50576 debug optional asterisk-mp3-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 8fadadf46222c96afb1b95efbe3214b2 1357944 comm optional asterisk-mp3_16.28.0~dfsg-0+deb11u3_armhf.deb 791e64fb4140a7cfd6bc6d0cfcb91338 134656 debug optional asterisk-mysql-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 6b506eb8642c3b2a6e8cdf69993cfe29 1375288 comm optional asterisk-mysql_16.28.0~dfsg-0+deb11u3_armhf.deb 36ef149d2b8b98603d3916084dd49135 1469100 debug optional asterisk-ooh323-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 06263a38ec747e6beee173bf50894072 1631772 comm optional asterisk-ooh323_16.28.0~dfsg-0+deb11u3_armhf.deb 075f3e5adf188888e3bc9036f6136d89 1433292 debug optional asterisk-tests-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 2db1a5d302b6ad70c1242d94baf3cf7c 1808744 comm optional asterisk-tests_16.28.0~dfsg-0+deb11u3_armhf.deb 6da068f4d854f983e60e3086c72d823f 272104 debug optional asterisk-voicemail-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb c5b503d0707af7c22597d979e64a6779 320660 debug optional asterisk-voicemail-imapstorage-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 35c126a93fc0612748f04880bb41212e 1454448 comm optional asterisk-voicemail-imapstorage_16.28.0~dfsg-0+deb11u3_armhf.deb fa94076a0622d265a4df90377f4a41e1 285544 debug optional asterisk-voicemail-odbcstorage-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 1a4bafb488c76e27b1faa9c0c93f3fcb 1441664 comm optional asterisk-voicemail-odbcstorage_16.28.0~dfsg-0+deb11u3_armhf.deb 0d3e0c07212fce2296abe9c7c7fcf6af 1435748 comm optional asterisk-voicemail_16.28.0~dfsg-0+deb11u3_armhf.deb 1748696e5f8eaf9be81cd7ba7db880a1 69972 debug optional asterisk-vpb-dbgsym_16.28.0~dfsg-0+deb11u3_armhf.deb 2974dbb0fabb42dcadeb773264615a60 1362604 comm optional asterisk-vpb_16.28.0~dfsg-0+deb11u3_armhf.deb b7d2f84c1f5a275d8380cf579a2f19f0 27500 comm optional asterisk_16.28.0~dfsg-0+deb11u3_armhf-buildd.buildinfo 7e3c26930617f0d1fd94ad3b686487e9 2221012 comm optional asterisk_16.28.0~dfsg-0+deb11u3_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEU5Ohx66NeEdc9V4jWTHLDRjMKsQFAmSUVVwACgkQWTHLDRjM KsRVMBAAoqhpiEiXqwZZ7bpPF6/YvPpXM8CQWNFCgkU1LvAIPXKdPM0rOINzwV7N SPKn4u5xJsnWJ5uCDuK+G7VAxfUwbOi4VK82ncAC8v1uUzYT7CzZEdwlfRdy/ksq oCxOInM//fIDtDG4FrD5Goo6UmV2wc3kdFVeYOe5eFfdA+1r9CosodSg5nPD2PiW iLqb22C6vVAXtr2mr+hoDbWQP/DctzWbqIN+8i/AP1GKDWhoSrck4m/Eu9R8kPvD Q2DCNGSU34YWt17Nu/ggU9rNYfDlcjqlTdqQj+j3+foiGa2e/2sL7bJouiCLgD3t e/Kzum8Oq1jqOkEIb1Ng9N+IGy/VhAS/njU0sy5g/PpjRZiOPj4A8TyLdu9SVhpi BRQQmnqEc9G3kDXM8/6gHAXq673hvXgGQZN6ue/bEb8/z29lG/CtXMcDUnrWhxAm YWoz2IrQvK/GMb+RmA9xgRwAkakfid8BCpOPc+S4aZpld/oFMGOoitpEi8bcvwoi xguPpNw7J1obnneK6oxiNqe7nM7Zoom4CAIgnojTJzs3a2E0BuA/euUfHYfxsCWc HPujd3fTvu65GOUcTBOp2fiMxptlDTkkO5I6SKC3RlQCj37mE1oo32xtdYvd1Iqs lwR7kmr34pUXwCRNeRaXyU9NKhx4HzQLlV5b+lGI/0guDQWU6qo= =z0QC -----END PGP SIGNATURE-----